-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2018.0061
           A vulnerability has been identified in Tenable Nessus
                               20 March 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Tenable Nessus
Operating System:     Windows
                      UNIX variants (UNIX, Linux, OSX)
Impact/Access:        Increased Privileges -- Existing Account
Resolution:           Patch/Upgrade
CVE Names:            CVE-2018-1141  
Member content until: Thursday, April 19 2018

OVERVIEW

        A vulnerability has been identified in Tenable Nessus prior to version
        7.0.3. [1]


IMPACT

        The vendor has provided the following details regarding the 
        vulnerability:
        
        "When installing Nessus to a directory outside of the default 
        location, Nessus did not enforce secure permissions for 
        sub-directories. This could allow for local privilege escalation if
        users had not secured the directories in the installation location."
        [1]


MITIGATION

        The vendor advises users should upgrade to the latest version of 
        Tenable Nessus and Nessus Enterprise to resolve these issues. [1]


REFERENCES

        [1] [R1] Nessus 7.0.3 Fixes One Vulnerability
            https://www.tenable.com/security/tns-2018-01

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWrCE7Ix+lLeg9Ub1AQihDw//QMdRMKypZCcYDB7TKnDMU9HBB3s83ODL
9afWJxFWMyoqgplW+iRgtr50jXWqXNmDQlutoSaEhppeBDKmVHbOnCwxK+gbZquz
Bk8s+JVDtcXON2PBuqOcCUVDZLocFzdWClQ393ZK2L5xSuZ7a0Lkz5I1eprwGLlr
L100aPMAsWH4lvzX16mYR/HIduMIg4VxBajyU/20hWGQS3KvS3wB9qcQf78orHyt
EVNrhO8sFSxbJU1zIJmSC3oWXpnzPNMyWb8BHybqo3Dcw+bNqrCNp1OGSbiyPaPG
Uor7SBXnWLzVm9uhfSoZlSDkUeoXSQIYn7V9ig+01c9Me+Uh7uhdwsiyJO2O3ba4
4sL7hEI9In185v+lhTYAbFL0XiSYbp1JCWY+gan6EjHfvq5DEczQUxmdPMwsxXEs
UNHGf/a6MtS0NLbA4n4VIioc5FszH1JzONf8Nat+6kC0WY5mliy59ircKOcXnp4n
KgBbzEaJBHKqSYLTQPXYZXA9STwXcqY+fhxk2BYJqrPE1x3P/OYdETvJrqpkaodh
fsY9Xx6rpZb71tkHbryomX2n89bhGR8AR+K0z+6wWqoh9zh2JZGRPCSFol3LiFOt
1fI3DffpWOwtRcDOkudReUx+mkSpMnOPVSQjbiigSlRVVpUSHYwfW558NyDkDcIv
d1T15xb4enk=
=3GN6
-----END PGP SIGNATURE-----